Roles
Settings Roles configures what each role can do. The table lists every role with its key, a System badge for platform-managed roles, a description, and live user and team counts. Search, sort, and column controls plus advanced filters find roles fast; New role starts a custom one. Role assignment itself happens in /settings/people, not here.
The system rows visible are Owner (owner, top in-tenant role with org-wide scope), Standard (standard, default authenticated user role), Admin (admin, can manage Object Manager), Partner Admin (partner_admin, PRESHai partner role), Platform Ops (platform_ops, in-org operational support role), and Superadmin (superadmin, full tenant administration role).
- Keys are the stable identifiers (for example
platform_ops). Names display; keys join. - System badge means platform-managed. Custom roles you add do not carry it.
- User and team counts show where each role is actually granted. A zero count means the role exists but nobody holds it right now.
- Pair this surface with Roles and membership: that page is the granting model (smallest sufficient role, pairing before solo approvals, admin count), this page is the table it grants into.

Granting checklist
Section titled “Granting checklist”- Person signed in at the correct tenant hostname first (grants land in this tenant)
- Smallest sufficient role selected in People
- Operator-level grants: paired on live approvals before solo approval rights
- Change communicated: what they can now do, and where the relevant guide is
- New holders spot-checked later: review first approvals, not just the grant
What next
Section titled “What next”- People: where members and their roles are managed.
- Security: SSO, directory sync, and group to role mapping.
- Roles and membership: the full granting and offboarding model.

